Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
ADTP Regulatory Watch· October 8, 2026· Swedish Data Protection Authority (IMY)
ImpactModerate 57
Type💰 Fine
Statusdecidedcase outcome
JurisdictionEU-SE
What happened
The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate technical and organisational safeguards, including real‑time intrusion monitoring, after a cyberattack exposed data of 2.2 million individuals.
Penalty
administrative fine of SEK 1 800 000 (approximately EUR 160 000)
Why it matters for trust and compliance
Its status is decided. The case has an outcome that others may cite.
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
Penalty: administrative fine of SEK 1 800 000 (approximately EUR 160 000).
It relates to GDPR. The regulations library explains what that law requires.
Who is affected
technologygovernmentprocessorMiljödata i Karlskrona
Recommended actions
Map the security requirements to existing controls and close gaps.
Check breach-notification procedures and timelines against the requirement.